ARN

ChoicePoint to pay $275,000 for second data breach

A 2008 data breach resulted from a security tool that was turned off for four months, the FTC says

Data broker ChoicePoint, the victim of a 2004 data breach affecting more than 160,000 U.S. residents, has agreed to strengthen its data security efforts and pay to compensate potential victims of identity theft for a second breach in 2008, the U.S. Federal Trade Commission said Monday.

ChoicePoint, now a subsidiary of Reed Elsevier, will pay US$275,000 to resolve the newest FTC complaint.

The FTC accused the company of failing to implement a comprehensive information security program to protect consumers' personal information, as required by the agency after the 2004 breach.

The April 2008 breach compromised the personal data of 13,750 people, the FTC said in a press release.

ChoicePoint turned off a "key" electronic security tool used to monitor access to one of its databases, and failed to detect that the security tool was turned off for four months, the FTC said.

For a 30-day period, an unknown hacker conducted more than 800 unauthorized searches of a ChoicePoint database containing sensitive consumer information, including Social Security numbers, the FTC said. After discovering the breach, the company notified the FTC.

If the software tool had been working, ChoicePoint likely would have detected the intrusions "much earlier," the FTC said.

A ChoicePoint representative wasn't immediately available for comment on the new court order.

Under a modified court order, ChoicePoint is required to report to the FTC detailed information about how it is protecting the breached database and certain other databases and records containing personal information.

The ChoicePoint reports are required every two months for two years.

The 2004 data breach, reported by ChoicePoint in 2005, resulted in at least 800 cases of identity theft, the FTC said.

A settlement and 2006 court order required the company to $15 million in civil penalties and consumer redress.

In the earlier settlement, ChoicePoint agreed to maintain procedures to ensure that sensitive consumer reports were provided only to legitimate businesses for lawful purposes; to maintain a comprehensive data security program; and to obtain independent assessments of its data security program every other year until 2026.

Newsletters
Sign up for our ARN newsletters!

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Enter the fully qualified URL, eg. http://www.example.com/
Users posting comments agree to the ARN comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Syndicate content Syndicate content Syndicate content Syndicate content Syndicate content Syndicate content Syndicate content Syndicate content Syndicate content Syndicate content
 
ARN Vendor Directory
Jobs
ARN Community Comments
ARN Library

Microsoft Anti-Piracy Infringement Alert

The Microsoft Anti-Piracy Newsletter outlines what Microsoft is doing to protect your business from Software Piracy and highlights recent legal action taken against those who infringe our copyright.

Subscribe to ARN

ARN has been the premier provider of information to the Australian IT channel for more than 12 years. As the only weekly publication dedicated to the channel, ARN produces timely, accurate news and analysis about IT business issues, products and services, new technology and market opportunities.